Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
什么是越权访问(IDOR),以及如何测试?
xbow.com
| 博客 |
#ai-security
|
#pentesting
|
#access-control
|
#web-security
|
#idor
|
#vulnerability-testing
摘要
XBOW 科普越权访问(IDOR):URL、表单与 API 中的对象级授权失效,介绍读/写两类变体、防护措施以及 AI 驱动测试的思路。
发布时间
2026-05-06 12:00
收录时间
2026-07-25 15:35
原文 ↗
相关内容
加固不安全的对象
(labs.cognisys.group)
Jason Haddix:别再惧怕 AI 渗透测试
(aikido.dev)
不安全的直接对象引用:隐藏在眼皮底下的授权漏洞
(bugbunny.ai)
黄金角色:一个简单的 API 逻辑缺陷如何打开整个 SaaS 平台
(labs.cognisys.group)
Practical Side-Channel Attacks in Web Applications
(blog.sentry.security)
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
(samcurry.net)
返回